blob: 443119e59c5125733c605b464be5aacc3256c9a7 [file] [log] [blame]
shubangf8ab3eb2020-09-11 17:50:45 -07001# mediatuner - mediatuner daemon
2type mediatuner, domain;
3type mediatuner_exec, system_file_type, exec_type, file_type;
4
5typeattribute mediatuner coredomain;
6
7init_daemon_domain(mediatuner)
8hal_client_domain(mediatuner, hal_tv_tuner)
9
10binder_use(mediatuner)
11binder_call(mediatuner, appdomain)
12binder_service(mediatuner)
13
14add_service(mediatuner, mediatuner_service)
15allow mediatuner system_server:fd use;
16
17###
18### neverallow rules
19###
20
21# mediatuner should never execute any executable without a
22# domain transition
23neverallow mediatuner { file_type fs_type }:file execute_no_trans;
24
25# do not allow privileged socket ioctl commands
26neverallowxperm mediatuner domain:{ rawip_socket tcp_socket udp_socket } ioctl priv_sock_ioctls;
27